TA416 APT Rebounds With New PlugX Malware Variant
#1
Information 
Quote:The TA416 advanced persistent threat (APT) actor is back with a vengeance: After a month of inactivity, the group was spotted launching spear-phishing attacks with a never-before-seen Golang variant of its PlugX malware loader.
 
TA416, which is also known as “Mustang Panda” and “RedDelta,” was spotted in recent campaigns targeting entities associated with diplomatic relations between the Vatican and the Chinese Communist Party, as well as entities in Myanmar. The group was also spotted recently targeting organizations conducting diplomacy in Africa.
 
In further analysis of these attacks, researchers found the group had updated its toolset — specifically, giving its PlugX malware variant a facelift. The PlugX remote access tool (RAT) has been previously used in attacks aimed at government institutions and allows remote users to perform data theft or take control of the affected systems without permission or authorization. It can copy, move, rename, execute and delete files; log keystrokes; fingerprint the infected system; and more.

“As this group continues to be publicly reported on by security researchers, they exemplify a persistence in the modification of their toolset to frustrate analysis and evade detection,” said researchers with Proofpoint, in a Monday analysis. “While baseline changes to their payloads do not greatly increase the difficulty of attributing TA416 campaigns, they do make automated detection and execution of malware components independent from the infection chain more challenging for researchers.”

Read more: https://threatpost.com/ta416-apt-plugx-m...nt/161505/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Forced bios update
Hey! I’ve run into s...BrynnD — 10:03
Surfshark VPN : Award-winning VPN servi...
Surfshark Apps Ver...jasonX — 07:34
Surfshark VPN : Award-winning VPN servi...
How to unblock block...jasonX — 07:11
K-Lite Codec Pack 19.6.8 / 19.6.8 Update
Changes in 19.6.8:...harlan4096 — 07:02
AdGuard for Windows 7.22.7
AdGuard for Window...harlan4096 — 07:01

[-]
Birthdays
Today's Birthdays
avatar (45)wapedDow
Upcoming Birthdays
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo

[-]
Online Staff
There are no staff members currently online.

>